Re: why DROP in PREROUTING

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, 27 Oct 2006 11:59:58 +0200
Gáspár Lajos <swifty@xxxxxxxxxxx> wrote:

> You can filter all of these packets at one point no matter where they 
> coming from and going to....

Oscar is against it in his tutorial, he even says a reason. If I
remember correctly, it's beacuse only the first packet hits that rule,
and others get the same action without further checking, and that's not
a good idea to do.



-- 
|   Jakov Sosic   |   ICQ: 28410271   |   PGP: 0x244F89CA   |
| http://jsosic.homeunix.org  |  jsosic@xxxxxxxxxxxxxxxxxxx |
--



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux